
Calhoun 

iniQiuiic^iul Ar{hiv« of tilt Mil vdl Poii^roduiit School 


Calhoun: The NPS Institutional Archive 
□Space Repository 



Theses and Dissertations 


1. Thesis and Dissertation Collection, all items 


2014-06 

Information technology program 
management: is there a difference? 


Allen, Jannes D. 

Monterey, California: Naval Postgraduate School 


http://hdl.handle.net/10945/42573 


This publication is a work of the U.S. Government as defined in Title 17, United 
States Code, Section 101. Copyright protection is not available for this work in the 
United States. 

Downloaded from NPS Archive: Calhoun 



DUDLEY 

KNOX 

LIBRARY 


htt p://w ww. n ps. e du/l ib ra ry 


Caflwuo is the Naval Postgraduate School's public access digital repository for 
research mate rials and institutiional publicatkios created by the NPS community. 
Calhoun is named for Professor of Mathematics Guy K. Caftiouo, NPS's first 
appointed — and published — schoteily author. 

Dudley Knox Library / Naval Postgraduate School 
411 Dyer Road / 1 Univefsity Circle 
Monterey, California USA 93943 







NAVAL 

POSTGRADUATE 

SCHOOL 

MONTEREY, CALIFORNIA 


MBA PROFESSIONAL REPORT 


INFORMATION TECHNOLOGY 
PROGRAM MANAGEMENT: 
IS THERE A DIFFERENCE? 


By: James D. Allen 

June 2014 


Advisors: John Dillard, 

Douglas Brinkley 


Approved for public release; distribution is unlimited 








THIS PAGE INTENTIONALLY LEET BLANK 



REPORT DOCUMENTATION PAGE 


Form Approved 0MB No. 0704-0188 


Public reporting burden for this collection of information is estimated to average 1 hour per response, including the time for reviewing instruction, 
searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send 
comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing this burden, to 
Washington headquarters Services, Directorate for Information Operations and Reports, 1215 Jefferson Davis Highway, Suite 1204, Arlington, VA 
22202^302, and to the Office of Management and Budget, Paperwork Reduction Project (0704-0188) Washington DC 20503. 


1. AGENCY USE ONLY (Leave blank) 2. REPORT DATE 3. REPORT TYPE AND DATES COVERED 

June 2014 MBA Professional Report 


4. TITLE AND SUBTITLE 5. EUNDING NUMBERS 

INFORMATION TECHNOLOGY PROGRAM MANAGEMENT: 

IS THERE A DIEEERENCE? 


6. AUTHOR: James D. Allen 


7. PEREORMING ORGANIZATION NAME(S) AND ADDRESS(ES) 

Naval Postgraduate School 
Monterey, CA 93943-5000 


9. SPONSORING /MONITORING AGENCY NAME(S) AND ADDRESS(ES) 

N/A 


8. PEREORMING ORGANIZATION 
REPORT NUMBER 


10. SPONSORING/MONITORING 
AGENCY REPORT NUMBER 


II. SUPPLEMENTARY NOTES The views expressed in this thesis are those of the author and do not reflect the official policy 
or position of the Department of Defense or the U.S. Government. IRB Protocol number N/A_. 


12a. DISTRIBUTION / AVAILABILITY STATEMENT 

Approved for public release; distribution is unlimited 


13. ABSTRACT (maximum 200 words) 


12b. DISTRIBUTION CODE 


The federal government spends billions of dollars on information technology (IT) projects each year. Despite 
spending billions on IT, the government has achieved little of the productivity improvements that private industry has 
realized from IT. Too often, federal IT projects run over budget, behind schedule, or fail to deliver promised 
functionality. The March 2009 Defense Science Board concluded that three root causes emerged from a review of 
major IT acquisition programs where cost, schedule, and performance were issues. First, senior leaders lacked 
experience and understanding. Second, the program executive officers and program managers had inadequate 
experience. Third, the acquisition process was bureaucratic and cumbersome, where many who were not accountable 
had to say “yes” before authority to proceed. To address these concerns, the U.S. Chief Information Officer, the 
Office of Personnel Management, and the Office of Management and Budget launched an initiative to strengthen 
program management by designing a formal IT Program Management career path. This research analyzes the need for 
IT Program Managers (PM) within the federal government by comparing the differences between IT PMs and non-IT 
PMs. 


14. SUBJECT TERMS 

Information Technology, Program management, IT PM Competencies 


17. SECURITY 
CLASSIEICATION OE 
REPORT 

Unclassified 


NSN 7540-01-280-5500 


18. SECURITY 
CLASSIEICATION OE THIS 
PAGE 

Unclassified 


19. SECURITY 
CLASSIEICATION OE 
ABSTRACT 

Unclassified 


15. NUMBER OE 
PAGES 

57 


16. PRICE CODE 


20. LIMITATION OE 
ABSTRACT 


Standard Form 298 (Rev. 2-89) 
Prescribed by ANSI Std. 239-18 




























THIS PAGE INTENTIONALLY LEET BLANK 


11 



Approved for public release; distribution is unlimited 


INFORMATION TECHNOLOGY PROGRAM MANAGEMENT: 
IS THERE A DIFFERENCE? 


James D. Allen, Captain, United States Army 


Submitted in partial fulfillment of the requirements for the degree of 


MASTER OF BUSINESS ADMINISTRATION 


from the 


NAVAL POSTGRADUATE SCHOOL 
June 2014 


Authors: James D. Allen 


Approved by: John Dillard, Lead Advisor 


Dr. Douglas Brinkley, Second Reader 


William R. Gates, Dean 

Graduate School of Business and Public Policy 



THIS PAGE INTENTIONALLY LEET BLANK 


IV 



INFORMATION TECHNOLOGY PROGRAM MANAGEMENT: 

IS THERE A DIEEERENCE? 


ABSTRACT 


The federal government spends billions of dollars on information technology (IT) 
projects each year. Despite spending billions on IT, the government has achieved little of 
the productivity improvements that private industry has realized from IT. Too often, 
federal IT projects run over budget, behind schedule, or fail to deliver promised 
functionality. The March 2009 Defense Science Board concluded that three root causes 
emerged from a review of major IT acquisition programs where cost, schedule, and 
performance were issues. First, senior leaders lacked experience and understanding. 
Second, the program executive officers and program managers had inadequate 
experience. Third, the acquisition process was bureaucratic and cumbersome, where 
many who were not accountable had to say “yes” before authority to proceed. To address 
these concerns, the U.S. Chief Information Officer, the Office of Personnel Management, 
and the Office of Management and Budget launched an initiative to strengthen program 
management by designing a formal IT program management career path. This research 
analyzes the need for IT Program Managers (PM) within the federal government by 
comparing the differences between IT PMs and non-IT PMs. 


V 



THIS PAGE INTENTIONALLY LEET BLANK 


VI 



TABLE OF CONTENTS 


I. INTRODUCTION.I 

A. BACKGROUND.I 

B. PURPOSE.2 

C. RESEARCH QUESTIONS.2 

D. METHODOLOGY.2 

E. ORGANIZATION.2 

II. BACKGROUND OF INORMATION TECHNOLOGY PROGRAM 

MANAGEMENT.5 

A. CLINGER-COHEN ACT.5 

B. THE 25-POINT IMPLEMENTATION PLAN TO REFORM 

FEDERAL IT MANAGEMENT.6 

C. IT PROGRAM MANAGEMENT CAREER PATH GUIDE.7 

D. INFORMATION TECHNOLOGY ACQUISITION WORKFORCE.8 

III. DIFFERENCES IN INFORMATION TECHNOLOGY PROGRAM 

MANAGEMENT.II 

A. COMPETENCIES.II 

1. General Competency Model.12 

2. Technical Competency Model.12 

B. CERTIFICATIONS.13 

1. Defense Acquisition University.13 

2. Federal Acquisition Institute.16 

C. REGULATORY GUIDELINES AND POLICIES.18 

1. DOD Instruction 8500.0I-Cybersecurity/Information 

Assurance.19 

2. DOD Directive 5000.0I-The Defense Acquisition System.19 

3. DOD Directive 5000.02-0peration of the Defense Acquisition 

System.20 

4. DOD Directive 4630.05-Interoperahility and Supportahility of 

Information Technology and National Security Systems.21 

5. DOD Directive 8000.01-Management of the Department of 

Defense Information Enterprise.21 

6. Defense Acquisition Guidebook.21 

IV. ANALYSIS.23 

A. INTRODUCTION.23 

B. PM COMPETENCY ANALYSIS.23 

I. General vs. Technical Competency Models.23 

C. CERTIFICATION FOR IT PM.28 

1. DAU IT vs. FAI IT PM Certification Standards.28 

2. DAU IT vs. Non-IT PM Certification.30 

D. CYBERSECURITY/INFORMATION ASSURANCE (lA) 

CERTIFICATION.31 

vii 




































V. CONCLUSION.33 

A. SUMMARY.33 

B. RECOMMENDATIONS FOR FURTHER STUDY.34 

LIST OF REFERENCES.35 

INITIAL DISTRIBUTION LIST.39 


viii 








LIST OF FIGURES 


Figure 1. 


Most Important Skills to Successfully Manage Highly Complex Projects 
(from PMI, 2013 ). 


24 


IX 




THIS PAGE INTENTIONALLY LEET BLANK 


X 



LIST OF TABLES 


Table 1. IT Program Management General Competency Model (from 0PM, 2011)... 12 

Table 2. IT Program Management Technical Competency Model (from 0PM, 

2011).13 

Table 3. Information Technology Level 1 Certification Standard (after DAU, 2014) ..14 

Table 4. Program Management Level 1 Certification Standard (after DAU, 2014).14 

Table 5. Information Technology Level 1 Certification Standard (after DAU, 2014) ..15 

Table 6. Program Management Level 2 Certification Standard (after DAU, 2014).15 

Table 7. Information Technology Level 3 Certification Standard (after DAU, 2014) ..16 

Table 8. Management Level 3 Certification Standard (after DAU, 2014).16 

Table 9. Federal Acquisition Certification for Program and Project Managers 

(FAC-P/PM) (from FAI, 2014).17 

Table 10. Federal Acquisition Certification for Program and Project Managers 

Core-plus IT Specialization (FAC-P/PM-IT) (from FAI, 2014).18 

Table 11. Technical Competencies for IT (after 0PM, 2011).25 

Table 12. Commonly Identified Critical Success Factors across Seven Successful IT 

Investments (from GAO, 2011).26 

Table 13. Investments Identified as Successful by Federal Departments (from GAO, 

2011).27 












THIS PAGE INTENTIONALLY LEET BLANK 



LIST OF ACRONYMS AND ABBREVIATIONS 


CCA 

CIO 

DAB 

DAU 

DOD 

FAC-P/PM 

FAC-P/PM-IT 

FAI 

FARA 

FL 

GAO 

IT 

ITMRA 

IT PM 

KLP 

NDAA 

NPS 

NSS 

OFPP 

0MB 

0PM 

USD (AT&L) 
USDA 


Clinger-Cohen Act 
Chief Information Officer 
Defense Acquisition Board 
Defense Acquisition University 
Department of Defense 

Federal Acquisition Certification for Program and Project 
Managers 

Federal Acquisition Certification for Program and Project 
Managers with core plus specialization for IT 

Federal Acquisition Institute 

Federal Acquisition Reform Act 

functional leader 

Government Accountability Office 
information technology 

Information Technology Management Reform Act 

information technology program manager 

key leadership position 

National Defense Authorization Act 

Naval Postgraduate School 

national security systems 

Office of Federal Procurement Policy 

Office of Management and Budget 

Office of Personnel and Management 

Under Secretary of Defense for Acquisition, Technology, & 
Logistics 

Department of Agriculture 


xiii 



THIS PAGE INTENTIONALLY LEET BLANK 


XIV 



ACKNOWLEDGMENTS 


I would like to thank Mr. John Dillard for his time, support, and encouragement in 
working on this project. I would also like to thank Mr. Raymond Jones for taking the time 
to share his personal views on information technology program management. Lastly, I 
would like to thank my project editor, Joy Jul, for her dedication and hard work. 


XV 



THIS PAGE INTENTIONALLY LEET BLANK 


XVI 



I. 


INTRODUCTION 


A. BACKGROUND 

The federal government spends billions of dollars on information technology (IT) 
projects each year. Investing in the federal government IT infrastructure is crucial to the 
efficient operation of federal programs and in many cases to our national security (S. Hrg, 
110-409). Despite spending billions on IT, the government has achieved little of the 
productivity improvements that private industry has realized from IT. Too often, federal 
IT projects run over budget, behind schedule, or fail to deliver promised functionality 
(Kundra, 2010). The March 2009 Defense Science Board concluded that three root causes 
emerged from a review of major IT acquisition programs where cost, schedule, and 
performance were issues. First, senior leaders lacked experience and understanding. 
Second, the program executive officers and program managers had inadequate 
experience. Third, the acquisition process was bureaucratic and cumbersome, where 
many who were not accountable had to say “yes” before authority to proceed was 
granted. Among these problems, lack of experience dominated (OUSD[AT&L], 2009). 

To address these concerns, the U.S. CIO (Chief Information Officer), the Office 
of Personnel Management (0PM), and the Office of Management and Budget (0MB) 
launched several initiatives intended to improve the oversight and management of 
IT acquisitions. The first initiative came in 2010 when the White House introduced the 
25 Point Implementation Plan to Reform Federal Information Technology Management. 
One main topic of discussion focused on strengthening program management by 
designing a formal IT Program Management career path. In 2011, 0PM created a 
separate specialized job title, the IT program manager (PM), and published the IT 
Program Management Career Path Guide. In addition to these efforts, the DOD CIO 
published the IT Acquisition Workforce Strategic Plan in 2012. This plan focused on a 
wide-range of activities necessary to create a management structure to strengthen and 
grow a recognized cadre of IT PMs. 


I 



B. PURPOSE 


This research analyzes the need for IT PM positions within the federal 
government by comparing the differences of IT PMs and non-IT PMs. The government 
continues to spend billions on IT each year. Does having experienced IT PMs ensure 
programs are delivered on time, within budget, and with the promised capabilities? 
Likewise, can a non-IT PM ensure program success? 

C. RESEARCH QUESTIONS 

The primary research question is: “What are the fundamental similarities and 
differences between IT PMs and non-IT PMs?” The subsidiary research questions are: 

• What is the history of IT Program Management? 

• What are the required competencies of an IT PM? 

• What are the sources of education and training for an IT PM? 

D. METHODOLOGY 

This project uses the following methodology: 

• A literature search via the Internet, private and government databases, 
books and journals available in the Naval Postgraduate School Dudley 
Knox Library, and other available sources of relevant information. 

• Additional, new, or follow-up interviews and questions via phone or 
email. 

E. ORGANIZATION 

This study is organized into five chapters. Chapter I presents an overview of the 
challenges the federal government has had with managing information technology 
projects. Chapter II discusses the general background of IT Program Management 
including the supporting policies and regulations. Chapter III reviews the competencies 
and certifications of IT PMs compared to non-IT PMs. Chapter III also reviews the DOD 
Directives and Instructions that apply to IT PMs. Chapter IV draws conclusions from 

similarities and differences between IT and non-IT PMs. Chapter V suggests 

2 



recommendations for future research on Defense Acquisition University (DAU) and 
Federal Acquisition Institute (FAI) courses that provide training on developing the 
general competencies of IT PMs. 


3 



THIS PAGE INTENTIONALLY LEET BLANK 


4 



II. BACKGROUND OF INORMATION TECHNOLOGY 
PROGRAM MANAGEMENT 

A. CLINGER-COHEN ACT 

The Clinger-Cohen Act (CCA) was enacted by Congress on February 10, 1996 to 
reform and improve the way federal agencies acquire and manage IT resources (OIG, 
2000). This act may be cited as the National Defense Authorization Act of Fiscal Year 
1996. The CCA is comprised of two acts: the Information Technology Management 
Reform Act (ITMRA) (Division E) and the Federal Acquisition Reform Act (FARA) 
(Division D). The ITMRA and FARA were renamed the Clinger-Cohen Act for its co¬ 
sponsors: Rep. William Clinger, R-PA, and Senator William Cohen, R-ME 
(www.govexec.com). This act is significant because, for the first time in law, it 
established the position of Chief Information Officer (CIO) in major departments and 
agencies within the federal government. The CIO plays a critical leadership role in 
driving reforms to (1) help control system development risks; (2) better manage 
technology spending; and (3) succeed in achieving real, measurable improvements in 
agency performance (OIG, 2000). “CIOs are to monitor the performance of IT programs, 
evaluate the performance of those programs, and advise agency heads on continuing, 
modifying or terminating the programs or projects” (U.S. House, 1996, p. 2). 

The DOD CIO is the principle staff assistant and advisor to the Secretary of 
Defense for IT. This includes the national security systems, defense business systems, 
and information resource management (IRM) matters. The DOD CIO is responsible for 
all matters relating to the DOD information enterprise including: communications, 
spectrum management, network operations, information systems, cybersecurity, position, 
navigation, timing (PNT) policy, and the DOD information enterprise that supports DOD 
command and control (DODD 5144.2, 2013). 

Prom an acquisition perspective, the DOD CIO will develop and maintain, in 
coordination with the Under Secretary of Defense for Acquisition, Technology, and 
Eogistics (USD (AT&E)), a process for maximizing the value of and assessing 

and managing the risks related to DOD IT acquisitions. This process will allow the CIO 

5 



to (1) be integrated with other key DOD deeision support systems and proeesses that 
support eapability identifieation, planning, programming, budgeting, and exeeution 
(PPBE) and aequisitions; (2) provide for analyzing, seleeting, monitoring, and evaluating 
DOD IT investments; and (3) be performanee- and results-based. The CIO also provides 
adviee on issues related to all assigned responsibilities and funetions of the Defense 
Aequisition Board (DAB), the Joint Requirements Oversight Couneil, and the Joint 
Capabilities Integration and Development System proeess (DODD 5144.2, 2013). 

B. THE 25-POINT IMPLEMENTATION PLAN TO REFORM FEDERAL IT 

MANAGEMENT 

On Deeember 9, 2010, the Federal CIO, Vivek Kundra, introdueed the 
implementation plan to reform federal IT management. This plan detailed the 25 steps 
federal ageneies must take to better manage large-seale IT programs and improve 
program aequisition, management, budgeting, governanee and aeeountability; and 
to migrate to eloud solutions when possible (www.fdeeieonneet.eom). Seetion B of the 
25 point implementation plan foeuses on strengthening program management within the 
federal government. A shortage of qualified personnel ereates ehallenges with program 
management aeross the federal government. Effeetively managing modular IT programs 
requires a eorps of program and projeet management professionals with extensive 
experienee and robust training. Strong program management professionals are essential 
to effeetively steward programs from beginning to end, manage the tension between on- 
time deliveries, and esealate issues for rapid resolution before they beeome roadbloeks 
(Kundra, 2010). 

0PM has taken steps to improve the IT Program Management talent in the federal 
government. These steps inelude ereating a eareer path to attraet and reward top 
performers, establishing integrated, multi-diseiplinary program teams with key skills 
before beginning major IT programs, requiring managers to share best praetiees at the 
elose of eaeh program, launehing a teehnology fellows program, and eneouraging 
mobility of program managers aeross the government (Kundra, 2010). Along with 
ereating a speeialized eareer path for IT PMs, a separate Oeeupational Series speeifie to 
IT Program Management would need to be established. The development of a 

6 



competency model for IT Program Management would also be required. 0PM worked 
with the Department of Treasury and the Department of Agriculture (USDA) to pilot the 
IT Program Management career track. After piloting the career paths at Treasury and 
USDA, 0PM plans to expand the career paths more broadly across the federal 
government (Kundra, 2010). 

C. IT PROGRAM MANAGEMENT CAREER PATH GUIDE 

In November 2011, the U.S. Office of Personnel Management (0PM), in 
collaboration with the Office of Management and Budget (0MB), developed the 
IT Program Management Career Path Guide in support of the U.S. CIO 25 Point 
Implementation Plan to Reform Federal Information Technology Management. The 
career path guide was developed to provide guidance to federal agencies interested in 
creating or enhancing their own IT Program Management career path (0PM, 201 Ib). The 
career path guide was based on the IT Program Management Competency Model 
established by 0PM in July 2011. It focuses on general and technical competencies 
pertinent to the IT Program Management career field (0PM, 2011b). This guide also 
provides a career progression plan for employees to move among and across jobs in 
Federal IT Program Management; presents a number of success factors enabling 
individuals to maximize Federal IT Program Management performance and career 
advancement. This guide identifies key work behaviors, training options, developmental 
opportunities, and lists common degrees and certifications completed by IT PMs in the 
federal sector. 

The IT Program Management Career Path Guide discusses the three job titles 
within the Job Family Standard for the Information Technology Management Series GS- 
2210. The three basic titles include IT Specialist, IT Project Manager, and IT Program 
Manager. The IT specialist does work that involves developing, delivering, and 
supporting IT systems (0PM, 201 la). The IT project manager manages IT projects to 
provide a unique service or product. The essential distinction between IT projects and 
other projects is that an IT project involves the delivery of an IT product, service, or 
system (0PM, 201 la). The IT PM oversees one or more major multi-year IT initiatives of 


7 



such magnitude that they must be carried out through multiple-related IT projects. 
The IT PM leads, coordinates, communicates, integrates, and assumes responsibility for 
the overall success of the program, ensuring alignment with critical agency priorities. IT 
PMs are responsible for ensuring the work efforts achieve the outcome specified within 
the agency’s business strategy, including appropriate strategic, life cycle management 
and capital IT investment plans. Work also includes project selection, prioritization, 
evaluation and monitoring, cost schedule management, risk management, quality 
management, and resource allocations (0PM, 2011a). 

Projects have a defined beginning and end while a program constitutes an ongoing 
operation. This is a key distinction between the two. A project serves to develop, modify, 
or enhance a product, service, or system and is constrained by the relationships among 
scope, resources, and time. A program encompasses the missions, functions, operations, 
activities, laws, rules, and regulations that an agency is authorized and funded by statute 
to administer and enforce. Additionally, a program provides products and/or services to 
the public, and agencies distribute available funding and provide ongoing staff support to 
carry out a continuing program (0PM, 2011a). 

D. INFORMATION TECHNOLOGY ACQUISITION WORKFORCE 

The IT Acquisition Workforce Strategic Plan is a plan that the Department of 
Defense (DOD) CIO developed to implement near term initiatives and to plan for longer 
term objectives associated with DOD’s IT acquisition reform movement (DOD, 2012). 
There are four guiding strategic goals which are discussed in this plan. The workforce 
strategic goals are (1) create a robust, sustainable IT acquisition and IT Program 
Management community; (2) develop a competency model and career roadmaps for IT 
acquisition and IT Program Management personnel; (3) sustain learning and growth 
throughout the professional life cycle; and (4) work across broad stakeholder 
communities to integrate IT acquisition reforms into IT acquisition curricula (DOD, 
2012 ). 

Of the four strategic goals. Goal 2 focuses on supporting the IT Program 
Management career field. There are four actions that support developing a competency 


8 



model and career roadmaps for IT acquisition and IT Program Management. The first 
action was to conduct a competency review for the IT acquisition workforce. The 
competency model identifies competencies and proficiencies required of employees as 
they move along that path (DOD, 2012). The DOD CIO initiated a comprehensive IT 
acquisition competencies’ review that aligned with a broader AT&L acquisition 
competency development effort to identify characteristics of successful IT acquisition 
workforce members (DOD, 2012). There was a four-phase process to build an IT 
acquisition workforce competency model. The four phases were (1) Competency 
Framework Development; (2) Competency Model Development; (3) Competency Model 
Testing & Refinement; and (4) Competency Assessment & Sustainment. The second 
action was to review IT acquisition career field certification requirements. This focused 
on entry-level and experience requirements. At the time of this writing, the IT acquisition 
career field certification rate was the lowest of any of the 14 acquisition fields. The IT 
functional leader (FL) was to review the requirements to determine the right mix of 
education, training, and experience needed to improve the workforce capability and 
quality. 

The third action was to develop senior-level IT acquisition capabilities. The IT FL 
will partner with AT&L to develop IT acquisition key leadership positions (KLP) within 
the IT acquisition career field. Individuals designated as KLPs have significant 
responsibilities and authorities and warrant special management attention for 
qualification and tenure requirements. The fourth action was to develop the IT Program 
Management career field. The 0PM, with input from agencies and the 0MB, began an 
effort in January 2011 to create a specialized career path for IT PMs (DOD, 2012). This 
initiative resulted in a separate occupational title specific to IT PMs being created within 
the current IT Management (2210) series. The 0PM also published the IT Program 
Management Career Path Guide (November 2011), which captured critical activities for 
agencies to achieve success in federal IT program management through recruitment, 
development, and retention of top talent (Kundra, 2012). 


9 



THIS PAGE INTENTIONALLY LEET BLANK 


10 



III. DIFFERENCES IN INEORMATION TECHNOLOGY 
PROGRAM MANAGEMENT 

A. COMPETENCIES 

Having skilled, competent, and professional program and project managers is 
essential to the success of programs. Unfortunately, the subject matter competencies 
required for successful IT system acquisition are too often missing in program managers 
responsible for program execution (OUSD[AT&L], 2009). In support of the White 
House’s 25 Point Implementation Plan, 0PM, 0MB, and the CIO council initiated a 
government-wide study to identify critical competencies for IT program and project 
management work. In 2011, the IT Program Management Competency Model was 
published to establish a baseline knowledge and skill requirement for managing IT 
programs. The competency model ensures that program and project managers possess the 
knowledge, skill, and ability necessary to advance in an IT Program Management career. 
The competency model also supports agency efforts in achieving success in Federal IT 
Program Management through workforce planning, training and development, 
performance management, recruitment, and selection (0PM, 2011). 

The competency model for IT program management is part of the IT Program 
Management Career Path Guide. The model is separated by category and grade level. The 
two categories that reference competencies are general and technical. The grade levels 
listed pertain to general schedule (GS) positions for GS-13, GS-14, and GS-15. For the 
DOD, a GS-13 is considered an entry-level management position. Within the Army, the 
position is filled by a Major/0-4. A GS-14 is considered to be a mid-level management 
position. Within the Army, the position is filled by a Lieutenant Colonel/0-5. A GS-15 is 
considered to be a senior-level management position. Within the Army, the position is 
filled by a Colonel/0-6. 


11 



1 


General Competency Model 


All program managers apply common knowledge, skills, and competencies when 
managing programs. The general competency model identifies the competencies required 
to be a program manager in the professional acquisition workforce (see Table 1). 


IT Program Management Competencies by Grade Level 



General Competencies 


Grad* 13 

Grad* 14 

Grade 13 

• Accountability 

• Accountability 

• Accountability 

• Attantion to 0*tail 

• Attention to Detail 

• Attention to Detail 

• Computer Skills 

• Computer Skills 

• Computer Skills 

• Conflict Management 

• Conflict Management 

• Conflict Management 

• Creative Thinking 

• Creative Thinking 

• Creative Thinking 

• Customer Service 

• Customer Service 

• Customer Service 

• Decision Making 

• Decision Making 

• Decision Making 

• Flexibility 

• Flexibility 

• External Av^reness 

> Influencing/Negotiating 

• Influencing/Negotiating 

• Flexibility 

» Integrity/Honesty 

• Integrity/Honesty 

• Influeneing/Negotiating 

» Interpersonal Skills 

• Interpersonal Skills 

• Integrity/Honesty 

• Leadership 

• Leadership 

• Interpersonal Skills 

• Learning 

• Learning 

• Leadership 

• Oral Communication 

• Oral Communication 

• Learning 

• Organizational Av/areness 

• Organizational Av^reness 

• Managing Human Resources 

• Planning and Evaluating 

• Partnering 

• Oral Communication 

• Problem Solving 

• Planning and Evaluating 

• Organizational Awareness 

• Reading Comprehension 

• Political Savvy 

• Partnering 

• Reasoning 

• Problem Solving 

• Planning and Evaluating 

• Self-Management 

• Reading Comprehension 

• Political Savvy 

• Strategic Thinking 

• Reasoning 

• Problem Solving 

• Teaching Others 

• Self-Management 

• Reading Comprehension 

• Teamwork 

• Strategic Thinking 

• Reasoning 

• Technical Competence 

• Teaching Others 

• Self-Management 

* Writing 

• Teamwork 

• Technical Competence 
■ Vision 

• Writing 

• Strategic Thinking 

• Teaching Others 
» Teamwork 

• Technical Competence 

• Vision 

» Writing 


Table 1. IT Program Management General Competency Model 

(from 0PM, 2011). 


2. Technical Competency Model 

In addition to the knowledge, skills, and competencies required of all program 
managers (see Table 2), specifically the IT PM also requires specific knowledge, skills, 
and competencies in managing IT programs. The technical competency model identifies 
the minimum competencies by position. This is required to specialize as an IT PM in the 
professional acquisition workforce. 


12 






















IT Program Management Competencies by Grade Level 


Technical Competencies 

Grade 13 

Grade 14 

Grade IS 

• Change Managennent 

• Configuration Management 

• Cott‘Ben«fit Analysis 

• Data Management 

• Information Assurance 

• Information Management 

• Information Resources Strategy 
and Planning 

• Project Management 

• Quality Assurance 

• Requirements Analysis 

• Risk Management 

• Systems Life Cycle 

• Systems Testing and Evaluation 

• Technology Awareness 

» Acquisition Strategy 

• Change Management 

» Configuration Management 

• Ccntracting/Procurement 

• Cost-Benefit Analysis 

• Financial Management 
» Information Assurance 

• Information Technology Program 
Management 

• Project Management 
» Quality Assurance 

• Requirements Analysis 

• Risk Management 

• Stakeholder Management 
» Systems Life Cycle 

• Technology Awareness 

» Acquisition Strategy 

• Capital Planning and Investment 
Assessment 

• Change Management 

• Compliance 

• Configuration Management 

• Contracting/Procurement 

• Cost-Benefit Analysis 

• Data Management 

• Enterprise Architecture 

• Financial Management 

• Information Assurance 

■ Information Management 

• Information Resources Strategy 
and Planning 

• Information Systems Security 
Certification 

• Information Technology 
Architecture 

• Information Technology Program 
Management 

• Project Management 

• Quality Assurance 

• Requirements Analysis 

• Risk Management 

• Stakeholder Management 

• Systems Engineering 

• Systems Life Cycle 

• Systems Testing and Evaluation 

• Technology Awareness 


Table 2. IT Program Management Technical Competency Model 

(from 0PM, 2011). 


B. CERTIFICATIONS 

Two institutions can certify IT and non-IT Program and IT Project Managers. The 
Defense Acquisition University (DAU) certifies DOD civilian employees and military 
Soldiers and Officers assigned. Also, it will include an assignment to an acquisition 
coded position (www.DAU.mil). The second is the Federal Acquisition Institute (FAI). 
They certify all federal employees of executive branch agencies. 

I. Defense Acquisition University 

In 1991, the Defense Authorization Act, Public Law 101-510 was instituted. It 
called for establishing an Acquisition Corps and professionalizing the acquisition 
workforce through education, training, and work experience (Garcia, Keyner, Robillard, 
& VanMullekom, 1997). As a result of this act, the Defense Acquisition Workforce 
Implementation Act was enacted to improve the effectiveness of personnel who managed 
and implemented defense acquisition programs. The Defense Acquisition University was 
established to: 


13 


















(1) Educate and train professionals for effeetive serviee in the defense 
acquisition system (2) aehieve more efficient and effeetive use of available 
acquisition resources by coordinating DOD acquisition education and 
training programs and tailoring them to support the eareers of personnel 
in aequisition positions and (3) develop edueation, training, researeh, 
and publication capabilities in the area of acquisition. (DODD 5000.57, 

1991, p. 2) 

Additionally, DAU would be responsible for the researeh and analysis of defense 
aequisition poliey issues from an aeademie perspeetive (PL 101-510, 1990). The training 
standards, requirements, and eourses have been modified over time to meet the ever- 
ehanging aequisition environment. 

To be eonsidered Level 1-eertified in IT, a DOD employee or military offieer has 
to meet the eore eertifieation standards found in Table 3. To be Level 1-eertified in 
Program Management, a DOD employee or military offieer has to meet the core 
certification standards found in Table 4. 


rF.RTIFTrATtON STANnARnS A- fORF PM'S DF\T 1 . 0 PMFNT Ol'IDF 

INFORMATIOV TFrHVOl OOV I F\TI 1 



Core Cerdikation Standards (RofunafacDAUiAcatfabaa) 

^r^tuiotiTraniif 

• .4CO IQl Ftaxiamfnmls of$>-gaBS Acqaiaboo Managemat 

' ■■rtiful Tniaiic 

• IRM 101 Basic Mormaboo Sx-stems Acqutstboii 

• or 

• S.\M 101 Basic Software AcqutsaioD Nlaaagciseni 


• Fomial cdDctfkn not required for ceniScatioo 

: tfrnrtrr 

• 1 vear of acquisiboo otpenence b irfcrmaticn teclixilof> 


Table 3. Information Technology Level 1 Certifieation Standard (after DAU, 2014) 


CERTIFICATION ST.\ND.\RDS & CORE PLl'S DEMLOPNENT GL IDE 

PROGR.A.\l management LEVEL 1 


Core CertiScation Standards (ReqiiRa for DA^iAcotfcifecm.) 1 

Tniiiat 

• .ACQ101 FuodxDeot^ of S>'staBS Acqubiboci Maoagemeot 

FtartiMul Tnkttt 

• SVS101 FoDdanent^ of Ss-stems Plaubg. Research. Deselopiaeii aod EogbeeiiDg 

• CLB 00* CostAn^'sis 

• CLV016 lotroducboQ to Earned Value NlaDagement 

[aafili*! 

• Formal edicaioa not required for cenj&aticiD 


• 1 s-earofacquisibooexpeneoce 

• 

• Effecthe 1 October 2014 the requaeoeot changes to: 

• 1 >-ear of acquisiboa experience siiib cost, scbedie, and performance respoasbibes 


Table 4. Program Management Level 1 Certifieation Standard (after DAU, 2014) 


14 

















To be considered Level 2-certified in IT, a DOD employee or military officer has 
to meet the core certification standards found in Table 5. To be Level 2-certified in 
Program Management, a DOD employee or military officer has to meet the core 
certification standards found in Table 6. 


CRRTmCATTON STAN’DARDS .t- CORF PI I S nFVTI OPMFST OfinF 

_ INFORMATION TECHNOLOGY LEVEL: _ 



Core Ceiti5catxm StaiHllfds(Reqw«4rfrDA«lAccrtfcdKm.) 

Ar^iuiliaa Tnuil| 

• ACO 20IA Iftenoediale S^’staos Acquisiboo. Pat A 

• ACQ 201B lotCTmediae Acqiisitioa. Pat B (R) 

t ■■riiMil Tnmia^ 

• IRM 202 I]«enD(diate IffonnabOD Ss-stoiu Acquisiboa (R) 


• Fonoal educaboa not leqtaed for ceiti6caboo 


• 2 ytm of acquisitioa npenence s ifotmaboo ted»olog>' 


Table 5. Information Technology Level 1 Certification Standard (after DAU, 2014) 


CERTmCATlON STANDARDS & CORE PLUS DEMLOPNENT GL IDE 

PROGRAM MANAGEMENT 1 F\T1 J 



Core Certification Standards (RequRdraDA^iAcotfoboa) 

Ar^iiiinaa Tniult 

• ACO 201A Ittetmodiae Acqiisiboo. Pat A 

* ACQ 201B Inomodiao $>*$ 1011 $ Acquckkn. Pat B (R) 

t ■■rfiMiI Traiiiac 

• PMT 251 Program Matagfloeot Toob Cowse, Pat I 

• PMT 25* Progran ManageiDent Took Coarse, Pan II 

• CON 111 Ccotract Plai^ 

• CON 124 Coolract Execubon 

• CON 12* Coatract Maoagemem 

• aiddiberoftbefcJkming ccaqiteted oo or after NV15.2005 

• SAM 101 Basic Softnare Acquisiboo Manageinai 

• or 

a IRM 101 Basic Ifformabon Ssstems Acquisiboa 

• 

• EffectrY 1 October 2014 the belo«'cowsc is added as arequrement 

• EVM 101 FuKUmenO^ cf Earned Value Managemeat 


• Fonoal educaboo not required for certficaboo 


• 2 v-ears of acquisiboD experience, aleast 1 v-ea of diise;q>enence must be in program management 


• Effectrve 1 October 2014 the reqiaement changes to: 

• 2 >'ean n program managerDent uiih cost, schedule, and performasce respoosUibes 


Table 6. Program Management Level 2 Certification Standard (after DAU, 2014) 


To be considered Level 3- certified in Information Technology, a DOD employee 
or military officer has to meet the core certification standards found in Table 7. To be 
Level 3-certified in Program Management, a DOD employee or military officer has to 
meet the core certification standards found in Table 8. 


15 














CERTIFIC ATION ;T.V.II.m)S A CORE PLUS DEMLQPNENT GUIDE 

INT0R.\iAT10N TECHNOLOGY LE\-EL3 


Core CertiScation Standards (Reqami for DAWiAccrttictfMo.) I 


• Nock Rtquaed 

(■■niMil Trttaiit 

• IRM 304 Ad\'aDced Ii^Ofniabcia Systems Acqnisibcio (R) 

• S.AM 301 Adi'aD:ed So^aie Acqaiskioo Managemeoi (R) 


• Fonnal ockcaboo oot roquved for ceit£caboo 

(i^nrtrr 

• 4 ytxs of kformaboo tediDok>g>’ or softaare-nteosn'e s>'stems acqiiskioa flcprrieoce 


Table 7. Information Technology Level 3 Certification Standard (after DAU, 2014) 


CERTIflCATlQN ST.AND.ARDS A CORE PLUS DEMLOPNIENT GL'IDE 


PROGRAM \U\AGEME\T LE\'EL3 



Core Certificabon Standards ?r,;jrrdfo(DAWiAc«tfcttoB) 

Tnntic 

• Nooe rrqwrd 

TraUif 

• BCF 103 FuxlaiKiii^ofBusaessFioaadalNlMiagtnKit 
*£OLljU FuDdamm^ofEanKdVakKMaiiagemeni 

• LOG 103 Rdiabdib', A^'aiabdit^^ aad Manranabfc- (RAM) 

• PMT 352.4 Program Managmient Office Course, Part A 

• PMT352B Profram NboagetDeit Office Course, Part B (R) 

• SYS 202 Imermedate System PtaDoio^ Resesch. DesdopoKat, ad EngneenDg. Part I 

• 

• Effective 1 October 2014, E\*M 101 becocues a Lesd II requireiDent tke a Level III requireinent 


• Formal edicatioa oot requked for ceit&atioa 


• 4 Yess acqoisiboQ experieoce utdt at least 

• - 2 ^ears ia a program office siidar organiutioa (dedicated mattn support to a PNL PEO, DCMA propam integrator, or supervisor of sfaipbuUog) 

• -1 >‘eariD a program mactagetDeotposilioQt^'ilh cost, schedule, and peifotmaDce respoosMibes 


• EffinttKe 1 October 2014 tbe requirement changes to: 

• 4 >'ears in prograi management nih cost, schedde and petformaoce 

• At least 2 years ia a prosram office or simdar orgaoizaboa (dedicated matrix support to a PM. PEO, DCMA progrmn alegrator. or sqperxisor of shgTbuddbg) These t«'o yeas ma>’ 
run coDcvrent 'nitb ffie preceding 4 reqiarement 

• OR 

• Ic'd ni DAWIA certfficatkn in a aaoffier acqmsitioo fboctioflal 

• 2 yeas in program management with cost, scbedie and petfomuDce 

• 2 >vas in a prt^an office or simiar orgaoizatioo (defeated matin support to a PNL PEO. DCMA program integrator, or sitpersisor of sli^pbuUiDg) These 2 years may nm 
coocurreot with the precedng Les'd III or 2 yea requremeats 


Table 8. Management Level 3 Certification Standard (after DAU, 2014) 

2. Federal Acquisition Institute 

The Services Acquisition Reform Act of 2003, Public Law 108-136, expanded 
the definition of acquisition to include functions performed by program and project 
managers (0MB, 2013). The Office of Federal Procurement Policy (OFPP) Policy Letter 
05-01— Developing and Managing the Acquisition Workforce —built upon this broader 
definition of acquisition workforce. It required the Federal Acquisition Institute (FAI) to 
make recommendations for a program and project management certification program 
(Administrator 0MB, 2007). FAI fosters and promotes the development of professional 
acquisition workforce personnel and performs a wide range of activities supporting the 
management of the acquisition workforce. 


16 














In April 2007, the Federal Acquisition Certification for Program and Project 
Managers (FAC-P/PM) was created to provide general training and experience 
requirements for program and project managers in civilian agencies. Individuals certified 
under the FAC-P/PM program met the general program management competencies and 
experience of the IT PM qualification guidance. They also had to meet the technical 
standards to fully satisfy the IT PM requirements. In July 2011, OFPP introduced the 
concept of a core-plus certification for IT acquisition professionals. The FAC-P/PM-IT 
was meant for those program and project managers responsible for the acquisition of IT 
assets. 

The FAC-P/PM is founded on “(1) core competencies that are considered 
essential for successful program and project management; (2) experience requirements; 
and (3) continuous learning to maintain skills currency” (Administrator 0MB, 2013, p. 
A-3). FAC-P/PM contains three levels of certification: entry-, mid- and senior-level. 
Program and project managers may only be certified at a certain level after they achieve 
all competencies for that certification level. FAC-P/PM certification requirements are 
detailed in Table 9. 



Table 9. Federal Acquisition Certification for Program and Project Managers 

(FAC-P/PM) (from FAI, 2014) 

17 


















The FAC-P/PM-IT is for PMs and project managers managing IT programs that 
support or have key integration functions with major non-IT programs. They shall be at 
least mid-level certified. PMs or project managers managing major IT programs shall 
hold senior level FAC-P/PM-IT specialization. The ability to specialize implies a 
demonstrated level of skill beyond the entry level. Thus, the IT specialization will be 
granted to holders of mid- and senior-level FAC-P/PMs. An acquisition workforce 
member can satisfy the core-plus competency requirements through training, education, 
other relevant certification programs, or demonstrated and documented through 
fulfillment of knowledge, skills, and abilities (Administrator 0MB, 2013). FAC-P/PM-IT 
certification requirements are detailed in Table 10. 



Table 10. Federal Acquisition Certification for Program and Project Managers 
Core-plus IT Specialization (FAC-P/PM-IT) (from FAI, 2014) 


C. REGULATORY GUIDELINES AND POLICIES 

The specific DOD guidelines and policies that pertain to IT PM are: the 25 Point 
Implementation Plan to Reform Federal IT Management; the IT Program Management 
Career Path Guide; and the IT Acquisition Workforce Strategic Plan. These guidelines 

18 



















and policies were covered in Chapter 11. The following directives and instructions apply 
to the management of information technology, but can be performed by IT or non-IT 
PMs. 


1. DOD Instruction 8500.01-Cybersecurity/Information Assurance 

Program managers must ensure cybersecurity requirements are identified and 
included throughout the life cycle of systems including acquisition, design, development, 
developmental testing, operational testing, integration, implementation, operation, 
upgrade, or replacement of all DOD IT supporting DOD tasks and missions (DODI 
8500.01, 2014). According to cybersecurity policy, “All IT that receives, processes, 
stores, displays, or transmits DOD information will be acquired, configured, operated, 
maintained, and disposed of consistent with applicable DOD cybersecurity policies, 
standards, and architectures” (DODI 8500.01, 2014, p. 4). DODI 8500.01 defines 
cybersecurity as: 

The prevention of damage to, protection of, and restoration of computers, 
electronic communications systems, electronic communications 
services, wire communication, and electronic communication, including 
information contained therein, to ensure its availability, integrity, 
authentication, confidentiality, and nonrepudiation, (p. 55) 

In addition to PMs managing the cybersecurity requirements throughout the life 
cycle, the DOD 8500.01 states acquisition personnel with “IT development 
responsibilities” are to be qualified in accordance with the Information Assurance 
Workforce Improvement Program. This requirement means a PM must obtain and 
maintain a certification corresponding to the highest level function performed. The DOD 
lA workforce is split into two major categories of Technical and Management. Both 
categories are comprised of three levels: I, II, and III. IT PMs would not perform lAT 
functions as they are technical in nature. 

2. DOD Directive 5000.01-The Defense Acquisition System 

The Defense Acquisition System exists to manage the nation’s investments in 

technologies, programs, and product support necessary to achieve the National Security 

Strategy and to support the United States Armed Forces (DODD 5000.01, 2007). This 

19 



directive describes the overarching management principles and mandatory policies. The 
areas that apply to programs containing information technology are Information 
Assurance, Information Superiority, and Interoperability. The Information Assurance 
section states that “Acquisition managers shall address information assurance 
requirements for all weapon systems; Command, Control, Communications, Computers, 
Intelligence, Surveillance, and Reconnaissance systems; and information technology 
programs that depend on external information sources or provide information to other 
DOD systems.” The Information Superiority section states the following: 

Acquisition managers shall provide U.S. Forces with systems and fa mi lies 
of systems that are secure, reliable, interoperable, compatible with the 
electromagnetic spectrum environment, and able to communicate across a 
universal information technology infrastructure, including national 
security systems (NSS), consisting of data, information, processes, 
organizational interactions, skills, analytical expertise, other systems, 
networks, and information exchange capabilities. (DODD 5000.01, 2007, 

p. 6) 

The Interoperability section states that: 

Systems, units, and forces shall be able to provide and accept data, 
information, materiel, and services to and from other systems, units, and 
forces and shall effectively interoperate with other U.S. Forces and 
coalition partners. Joint concepts and integrated [solution] architectures 
shall be used to characterize these interrelationships. (DODD 5000.01, 

2007, p. 7) 

Each section has a specific directive that provides details on how IT is applicable 
to program managers. 

3. DOD Directive 5000.02-0peration of the Defense Acquisition System 

The overarching management principles and mandatory policies that govern the 
Defense Acquisition System are described in DOD Directive 5000.01. This directive 
provides the detailed procedures that guide the operation of the system. Enclosure 11 
describes the requirements applicable to all programs containing information technology. 
Program managers that manage IT projects and/or programs have to comply with the 14 
policies and procedures contained in this directive. Even though the policies and 

procedures are specific to IT, any program manager can execute them. 

20 



4. DOD Directive 4630.05-Interoperability and Supportability of 
Information Technology and National Security Systems 

This directive requires IT and NSS employed by U.S. forces to interoperate with 
existing and planned systems and equipment of joint, combined, and coalition forces and 
with other U.S. government departments and agencies (DODD 4630.05, 2004). Program 
managers shall make certain that IT and NSS interoperability be verified early and with 
sufficient frequency throughout a system’s life. This also applies to changes affecting 
interoperability or supportability, to assess, evaluate, and certify its overall 
interoperability and supportability within a given capability (DODD 4630.05, 2004). 

5. DOD Directive 8000.01-Management of the Department of Defense 
Information Enterprise 

This section discusses the DOD Information Enterprise and its role in helping 
program managers describe their transition from the current environment to the future 
net-centric environment. Consistent with DODD 5000.01 and DODI 5000.02: 

Acquisition strategies shall appropriately allocate risk between the 
Government and contractor; effectively use competition; tie contract 
payments to performance; and, where practicable, take maximum 
advantage of commercial off-the-shelf and non-developmental item 
technology. Information solutions shall be structured into useful segments 
that are as narrow in scope and brief in duration as practical; each segment 
shall solve a specific part of an overall mission problem and deliver a 
measurable net benefit independent of future segments (DODD 8000.01, 

2009, p. 3). 

6. Defense Acquisition Guidebook 

Chapter VII of the Defense Acquisition Guidebook (DAG) discusses how DOD 
complies with statutory and regulatory requirements for acquiring IT and NSS. This 
includes using a network-centric strategy to transform DOD warfighting, business, and 
intelligence capabilities. This chapter also provides descriptions and explanations of the 
Clinger-Cohen Act and many other associated topics and concepts, and discusses many 
of the activities that enable the development of net-centric systems (DAG, 2012). 


21 



THIS PAGE INTENTIONALLY LEET BLANK 


22 



IV. ANALYSIS 


A. INTRODUCTION 

This chapter discusses the similarities and differences between IT PMs and non- 
IT PMs. The first section discusses the competencies that were identified in Chapter III. 
The second section reviews the certification requirements for becoming an IT PM. The 
remainder of this chapter covers the cybersecurity requirements for PMs charged with IT 
development responsibilities. 

B. PM COMPETENCY ANALYSIS 

An analysis between general and technical competencies was conducted to 
determine which competency model was essential in managing IT programs. 

I. General vs. Technical Competency Models 

The general competencies listed in Table 1 are required for all program managers. 
The higher a PM’s grade, the more competencies are required for that position. This 
study’s research discovered that general competencies are the most important for 
achieving success as a program or project manager. Leadership stands above all other 
competencies and is the primary role of a program manager. History has shown that 
without strong leadership, teams are likely to stray from sound fundamentals and 
implement high-risk shortcuts, placing the project in jeopardy (Forsberg, Mooz & 
Cotterman, 2005). A report conducted by the Project Management Institute (PMI) (Figure 
I) also identifies leadership as the most important skill to manage a program or project. 


23 



Most Important Skills to Successfully Manage Highly Complex Projects 


Lea<l«f$hip skills 1^^ 

81 °/^ 

Technical proj«t 

Bao/ 

management skills 1 1 

Wj/o 

Strategic and business 

l9% 

management skills ra 1 

Other 

ll% 


Source iu/j-.,. 

Nivu'. -- - - ?0t ~ pm 

Figure 1. Most Important Skills to Successfully Manage Highly Complex 

Projects (from PMI, 2013 ) 

PMs need to have good “soft skills” to achieve success on programs or projects. 
Some soft skills include communication, influencing, negotiating, conflict management 
and problem solving. For PMs to meet stakeholders’ needs and expectations, they must 
be able to communicate, negotiate, influence, and solve problems within their 
organization. PMs need to actively listen to their teams and assist in developing new 
approaches for solving problems and then influence the team to achieve the program or 
project goals. It’s important for PMs to have organizational awareness and political savvy 
to understand their social, physical, and political environment. Organizational issues are 
often the most difficult part of working on and managing projects (Schwalbe, 2006). 
Lastly, PMs must remain flexible to deal with the complex and rapidly changing 
environment when working towards program or project goals. 

The technical competencies listed in Table 2 are required for IT PMs. Not all of 
the competencies are IT-specific. By taking a closer look, some competencies are 
considered common knowledge and skills for all PMs. For example, cost-benefit analysis, 
requirements analysis, and risk management are all common skills a PM should possess. 


24 


Technical! Competencies 

Cradg 15 

* Acquiiitron Strategy 

' Capital PlaPPirig and tnvestmertt 
Asian men t 
» Change r^anagement 

* Complianca 

> Configuration Management 

* Contracting/PrO'Curement 

* Co*t"0«neht Analysis 

* Data Management 

* Enterprise Architecture 

* Financial Management 

* Information Assurance 

» Information Manageriient 
I Information Resources Strategy 
and Planning 

* Information Systems Security 
Certification 

* Information Technology 
Architecture 

* Information Technology Program 
Management 

» Project Management 

* Quality Assurance 

* Requirements Analysis 

* Risk Management 

■< Stakeholder Management 

* Systems Engineering 
» Systems Uf'e Cycle 

* Systems Testing and Evaluation 

* Tech n pi o gy Av^^ re nes S 


Table 11. Technical Competencies for IT (after 0PM, 2011) 


Of the 25 technical competencies listed in the GS-15 column, only 32% are 
considered IT-specific knowledge, skills, and abilities. The remaining 68% relate to 
knowledge, skills, and abilities of non-IT PMs. These statistics indicate that general 
competencies are more important than technical as they relate to the differences between 
IT and non-IT PMs. While it is recommended that IT PMs have some working 
knowledge in the field of IT, they do not necessarily have to be experts on any specific 
technology. PMs need to know enough to build strong teams and to ask the right 
questions. Consequently, it might be difficult for a PM with little or no experience in IT 


25 












to become the program manager of a large IT program or project. A potential setback 
could be earning the respect of the project team. But when a PM is an IT expert, the PM 
may only focus on enhancing technical skills. Some IT experts do not see how soft s ki lls 
or business skills will improve their performances or increase their salaries. This is 
another potential setback of selecting a PM with a strong background in IT. 

The Government Accountability Office (GAO) conducted a study which 
identified seven successful federal IT investments that achieved their respective cost, 
schedule, and performance goals. GAO identified nine common factors that were critical 
to the success of three or more of the seven IT investments. The nine critical success 
factors are shown in Table 12 and the Federal Department IT investments are shown in 
Table 13. 


Commonly IdentifiecJ Critical Success Factors across Seven Successful IT Investments 





Investments 




Critical success factors 

ORIS 

GCSS.J 

MOMentum 

WHTI 

ITWS 

CADE 2 

OHRS 

1 

Program ofBdals were actively engaged with 
stakeholders. 

X 

X 

X 

X 

X 

X 

X 

2 

Program staff had the necessary knowledge and 
skills. 

X 


X 

X 

X 

X 

X 

3 

Senior department arxJ ager>cy executives 
supported the programs. 

X 

X 


X 

X 

X 

X 

4 

End users arxj stakeholders were involved in the 
development of requirements. 

X 

X 

X 


X 


X 

5 

End users participated in testir>g of system 
functionality prior to formal ef>d user acceptance 
testir>g. 


X 

X 

X 

X 


X 

6 

Government and contractor staff were consistent 
arwj stable. 

X 

X 


X 

X 



7 

Program staff priohtized requirements. 


X 

X 


X 


X 

8 

Program oftidals maintained regular 
oommunicatioo with the prime contractor. 

X 


X 

X 



X 

9 

Programs received sufficient funding. 

X 



X 


X 



Seww: GAO etf aqtrcf 


Table 12. Commonly Identified Critical Success Factors across Seven 
Successful IT Investments (from GAO, 2011) 


26 















Investments Identified as Successful by Federal Departments 

Department 

Investment 

Commerce 

Decennial Response Integration System 

Defense 

Global Combat Support System-Joint. Inaement 7 

Energy 

Manufactunng Operations Management (MOMentum) Project 

Homeland Security 

Western Hemisphere Travel Initiative 

Transportation 

Integrated Terminal Weather System 

Treasury 

Customer Account Data Engine 2 (CADE 2) 

Veterans Affairs 

Occupational Health Record-keeping System 


Soirca: A^tncy daU. 


Table 13. Investments Identified as Successful by Federal Departments 

(from GAO, 2011) 


Of the nine critical factors listed, over half incorporated general competencies that 
contributed to the successful acquisition of IT investments. None referenced the program 
manager needing IT technical competencies to be successful. The GAO concluded their 
report by stating that the implementation of these factors will not necessarily ensure 
successful IT acquisitions; nevertheless, these factors may help federal agencies address 
the IT acquisition challenges. The following are comments cited from agency officials 
that participated in the report: 

• Internal Revenue Service (IRS) officials stated that consistent and open 
communication with internal and external stakeholders was critical to the 
success of their program. 

• National Nuclear Security Administration (NNSA) stated that notifying 
stakeholders of potential issues as soon as they were identified helped 
foster transparency and trust. 

• Customs and Border Protection (CBP) officials noted almost every 
member working on the team had a good understanding of acquisitions 
including an understanding of program management. 

• The NNSA selected a program manager from the end user organization as 
opposed to an individual with an IT background. The individual selected 
has decades of experience managing shop floor control systems. He was 
well aware of how the work on the shop floor was done and focused on 
safely delivering the necessary functional requirements to the end user. 


27 












• Veterans Affairs (VA) officials stated that ensuring a positive, non- 
adversarial relationship between prime contractor and the program 
management office was critical to the success of the investment. 

In conclusion, these examples demonstrate a program manager can successfully 
manage large, complex IT programs by combining program management knowledge with 
general competencies. 

C. CERTIFICATION FOR IT PM 

As stated in Chapter III, the two institutions that certify IT and non-IT program 
and project managers are DAU and FAT DAU certifies DOD civilian employees and 
military officers while FAI certifies all federal employees of the executive branch 
agencies. An analysis of the two institutions was conducted, and both share similarities 
and differences for developing and strengthening IT PMs. Both institutions cover the core 
competencies, but they differ on when the knowledge and experience is necessary for 
certification. FAI does not provide a specific curriculum for training and DAU IT 
certification lacks mandatory program management functional training. 

I. DAU IT vs. FAI IT PM Certification Standards 

FAI requires program managers seeking core-plus specialty in IT acquisitions be 
certified as mid-level program managers. PMs are also required to have at least two 
years’ experience in managing IT programs or projects. There are two certification levels 
for IT PMs: mid and senior. PMs that manage major IT investments will hold the senior 
level IT specialty. The certification requirements for entry-, mid-, and senior-level PM 
are listed in Table 1. In addition to program management entry- and mid-level 
competencies, PMs must achieve IT core-plus competencies prior to being granted 
PM core-plus IT specialization or IT PM certification. To be certified as entry, mid, 
and senior level, FAI requires program managers to demonstrate seven core PM 
competencies. The competencies required are: (I) Requirements Development and 
Management Processes, (2) Systems Engineering, (3) Test and Evaluation, (4) Eife 
Cycle Eogistics, (5) Contracting, (6) Business, Cost and Einancial Management, and 
(7) Eeadership. Each of these core competencies ensure program and project managers 


28 



possess the common skills and experience necessary to excel in the PM functional area. 
The competencies for IT-specialization are listed in Table 2. The majority apply to the 
senior-level position. As stated earlier, two years of experience is required to manage IT 
programs or projects. At a minimum, the experience must include the following: the 
identification of IT system requirements; the use or knowledge and familiarity of modular 
development methodologies; system integration into an Enterprise Architecture; and IT 
system testing and evaluation. FAI does not provide a specific curriculum for training. 
Training vendors are given the flexibility to tailor their instructional methods to deliver 
learning outcomes that align to the core competencies. FAI accepts training from multiple 
sources. These include industry training vendors, colleges and universities, and federal 
training institutions and academies. A list of providers offering PM certification training 
can be found on www.FAI.gov. The sources are updates periodically. 

According to DAU, civilians seeking certification in the IT acquisition career 
field can do so with no prior program management experience. Civilians can take two 
courses, have one year of IT experience, and meet the Fevel I IT requirement. Military 
officers assessed in the acquisition workforce are offered five career fields with program 
management and contracting being the most preferred. Officers are highly discouraged 
from applying for other DAU certifications until Fevel 3 of their functional area is 
achieved. The three certification levels for IT acquisitions are Fevel 1, Fevel 2, and Fevel 
3. The certification requirement for each level is listed in Tables 3, 5 and 7. DAU has a 
core-plus development guide that offers optional courses to obtain additional knowledge, 
skills, and abilities. Providing courses that are “mandatory” ensures that program and 
project managers possess the common skill and experience necessary for successful 
performance. Providing courses that are “optional” permit skill and experience to go 
undeveloped and, consequently, contribute to poor program and/or project management. 
DAU core-plus training for IT covers the same program management competencies as 
FAI throughout three levels. Feadership is covered during Fevel 3. As stated earlier, 
leadership is the most important skill when managing a program or project and should be 
introduced at Fevel 1—not Fevel 3. DAU does not have a published competency 
guideline to indicate what general and technical competencies need to be demonstrated 


29 



before obtaining the next level of certification. DAll’s core certification standards are 
geared toward meeting training and experience objectives. DAU does not specify what 
type of IT acquisition experience is required to meet the certification standard for any 
level. This shortcoming is another area that can go unchecked. Some DAU core-plus 
training requires a formal education; whereas, FAI has no such requirement on any of its 
PM courses. This deficiency can be seen as another reason for poor performing IT 
programs or projects within DOD. 

2. DAU IT vs. Non-IT PM Certification 

The IT PM core certification standards lack the mandatory PM training necessary 
to succeed at managing IT programs and projects. The training that provides knowledge, 
skill, and experience for managing programs and projects is not required in order to 
achieve a Level 3 certification. The IT core certification standard should include more 
mandatory training that would prepare an IT PM to take on an IT project and have more 
than just the fundamentals of acquisition management. When analyzing the program 
management certification standards, the process ensures that if some core-plus training is 
missed, the training becomes mandatory before certifying to the next level. Take 
contracting for example. The training is considered optional for Level 1 certification, but 
it is mandatory for Level 2. Developing the knowledge, skill, and experience in this field 
contributes tremendously to ensuring IT requirements are well-written. IT PMs with 
contracting experience are better equipped to help translate business and technical 
requirements into a statement of work that can help ensure a smooth procurement. 
Additionally, a well-written contract could accommodate the rapid change in technology 
and not require a contract modification later in the program. The only time contracting is 
offered to the IT PM is during Level 1 optional training. Information Assurance (lA)— 
now known as Cybersecurity—is offered as optional training for IT PM Level 2. This 
training should be part of the core certification standards for IT PM Level 1. It is offered 
as optional training for PM Level 1. lA is important because PMs must ensure lA 
requirements are identified and included throughout a system’s life cycle. The DAU IT 
PM core certification standards lack the mandatory PM training necessary. This leaves IT 


30 



PMs with inadequate skill and experience necessary for managing successful IT 
programs and projects. 

D. CYBERSECURITY/INFORMATION ASSURANCE (lA) 
CERTIFICATION 

Nothing separates an IT PM from a non-IT PM with respect to cybersecurity. A 
PM running a Major Defense Acquisition Program (MDAP) will have to meet the same 
cybersecurity requirements as an IT PM in-charge of a Major Automated Information 
Systems (MAIS) program. As stated in Chapter III, all program managers must ensure 
cybersecurity requirements are identified and included throughout the life cycle of a 
system. According to DODI 8500.01, acquisition personnel with IT development 
responsibilities shall be lA-qualified in accordance with DOD 8570.01-M, the lA 
Workforce Improvement Program. The lA Management (lAM) category is the logical 
position to apply for a PM. This position is considered to be the baseline for DOD 
requirements. A PM can obtain three levels of lAM. Once assigned to a position, a PM 
has six months to achieve the appropriate certification for that level. Program managers 
in the lAM category must remain certified during their time in that position or risk losing 
their certification status. 

As of March 14, 2014, Information Assurance has been renamed to 
Cybersecurity. The term “cybersecurity” has been adopted from the National Security 
Presidential Directive-54/Homeland Security Presidential Directive-23 and is to be used 
throughout DOD instead of the term “information assurance (lA).” 


31 



THIS PAGE INTENTIONALLY LEET BLANK 


32 



V. CONCLUSION 


A. SUMMARY 

The primary objective of this thesis was to explore the differences between IT 
program management and non-IT program management through the analysis of three 
categories: competencies, certifications, and regulatory guidelines and policies. The first 
area analyzed was the general and technical competencies listed in the IT program 
management competency model. The technical competency model revealed more 
common program management knowledge and skill than technical skill. This made the 
general competency model more important when managing an IT program or project. 
The second area analyzed was the certification curriculum provided by DAU and FAI for 
IT PMs. DAU and FAI share similarities and differences in developing and strengthening 
IT PMs, but FAI requires a more demanding prerequisite by concentrating on the seven 
core program management competencies. The last area analyzed was the regulatory 
guidelines and policies for the acquisition and management of IT systems. Three of the 
guidelines directly relate to IT program management, while the remaining policies focus 
on the acquisition and management of IT systems. Based on the results of the three 
categories analyzed, more similarities than differences exist between IT and non-IT 
program management. Each category requires the same knowledge and skill of 
fundamental program management principles. A program manager who can combine the 
fundamental principles—cost, schedule, and scope management—with interpersonal 
skills—leadership, communication, influencing, negotiating, conflict management, and 
team building—seems to more effectively manage any program or project. 

Managing the acquisition of IT systems continues to be a challenge for the federal 
government every year. Although 0MB has launched several initiatives to improve the 
management and oversight of IT acquisitions, there is still room for improvement. 
Creating a specialized career path and competency model for IT PMs was a great start, 
but the focus should be on developing and strengthening general competencies for all 
program managers. Numerous organizations train program managers on the technical and 


33 



managerial competencies of program management, but what training exists with focus on 
developing and strengthening general competencies? 

B. RECOMMENDATIONS FOR FURTHER STUDY 

As shown in this research, a program manager can successfully manage an IT 
program or project by combining program management knowledge and skills with 
interpersonal skills. Future research could explore the DAU and FAI courses currently 
available that provide training on developing the general competencies listed in the IT 
program management competency model. If no courses exist, research could determine 
what additional training could be implemented to develop the general competencies of 
program managers. 


34 



LIST OF REFERENCES 


Administrator, Office of Management and Budget (0MB). (2007, April 25). The Federal 
Acquisition Certification for Program and Project Managers [Memorandum]. 
Washington, DC: Author. 

Administrator, Office of Management and Budget (0MB). (2013, December 16). 
Revisions to the Federal Acquisition Certification for Program and Project 
Managers [Memorandum]. Washington, DC: Author. 

Andrues, W. (2006, July 11). The Clinger-Cohen Act: 10 years later. Retrieved from 

http://www.govexec.eom/federal-news/2006/07/the-clinger-cohen-act-10-years- 

later/22227/ 

Director, Office of Management and Budget (0MB). (2011, August 8). Chief 

Information Officer Authorities [Memorandum]. Washington, DC: Author. 

Department of Defense. (2007, April 23). Interoperability and supportability of 
Information Technology (IT) and National Security Systems (NSS) (DOD 
Directive 4630.05). Washington, DC: Author. 

Department of Defense. (2007, September). Defense acquisition guidebook. Retrieved 
from http://dag.dau.mil 

Department of Defense. (2009, February 10). Management of the Department of Defense 
Information Enterprise (DOD Directive 8000.01). Washington, DC: Author. 

Department of Defense. (2012, January 24). Information Assurance Workforce 
Improvement Program (DOD 8750.01-M). Washington, DC: Author. 

Department of Defense. (2012, April). IT acquisition workforce strategic plan. 
Washington, DC: Author. 

Department of Defense. (2013, April 22). DOD Chief Information Officer (DOD 
Directive 5144.02). Washington, DC: Author. 

Department of Defense. (2014, March 14). Cybersecurity (DOD Instruction 8500.01). 
Washington, DC: Author. 

Forsberg, K., Mooz, H., & Cotterman, H. (2005). Visualizing project management: 
Models and frameworks for mastering complex systems. Hoboken, NJ: John 
Wiley & Sons. 

Garcia, A., Keyner, H., Robillard, T.J., & VanMullekom, M. (1997). The Defense 
Acquisition Workforce Improvement Act: Five years ater. Washington, DC: 
Defense Acquisition University. 


35 



Government Accountability Office. (2009, April 28). Management and oversight of 
projects totaling billions of dollars need attention (GAO-09-624T). Retrieved 
from http://www.gao.gov 

Government Accountability Office. (2011, October). Critical factors underlying 

successful major acquisitions (GAO-12-7). Retrieved from http://www.gao.gov 

High-Risk Information Technology Projects: Is Poor Management Leading to Billions in 
Waste? Hearing before the Federal Financial Management, Government 
Information, Federal Services, and International Security of the Committee on 
Homeland Security and Governmental Affairs, 110th Cong. 2. (2007, September). 
(Statement by Honorable Thomas R. Carper, Chairman of the Subcommittee). 
Washington, DC: Government Printing Office. 

Kundra, V. (2010, December 9). 25 point implementation plan to reform federal 
information technology management. Washington, DC: Author. 

Office of Inspector General. (2000, July 17). NASA’s organizational structure for 
implementing the Clinger-Cohen Act. Washington, DC: Author. 

Office of Personnel Management. (2011, May). Joint family standard for administrative 
work in the Information Technology Group, 2200. Washington, DC: Author. 

Office of Personnel Management. (2011, November). IT program management career 
path guide. Washington, DC: Author. 

Office of the Under Secretary of Defense for Acquisition, Technology, and Logistics 

(OUSD[AT&L]). (1990). No. 101-510, § 1746, 104 Stat. 1653. Washington, DC: 
Defense Acquisition University. 

Office of the Under Secretary of Defense for Acquisition, Technology, and Logistics 
(OUSD[AT&L]). (2007, November 20). The defense acquisition system (DOD 
Directive 5000.01). Washington, DC: Author. 

Office of the Under Secretary of Defense for Acquisition, Technology, and Logistics 

(OUSD[AT&L]). (2009, March). Department of Defense policies and procedures 
for the acquisition of Information Technology. Washington, DC: Defense Science 
Board. 

Office of the Under Secretary of Defense for Acquisition, Technology, and Logistics 
(OUSD[AT&L]). (2013, November 25). Operation of the defense acquisition 
system (Interim DOD Instruction 5000.02). Washington, DC: Author. 

Project Management Institute. (2013, September). Pulse of the profession in-depth 
report: Navigating complexity. Retrieved from http://www.pmi.org 


36 



Safavian, D.H. (2005, April 15). Developing and Managing the Acquisition Workforce 
[Memorandum]. Washington, DC: Office of Federal Procurement Policy 

Schwalbe, K. (2006). Information technology project management (4th ed.). Toronto, 
Canada: Thomson Publishing. 

U.S. Department of State Foreign Affairs. (1990). National Defense Authorization Act of 
1990. Washington, DC: Author. 

U.S. House. (1996). Clinger Cohen Act of 1996, 40 U.S.C. §1401. Washington, DC: 
Author. 


37 



THIS PAGE INTENTIONALLY LEET BLANK 


38 



INITIAL DISTRIBUTION LIST 


1. Defense Technical Information Center 
Ft. Belvoir, Virginia 

2. Dudley Knox Library 
Naval Postgraduate School 
Monterey, California 


39 



